Tag

#npm

29 stories taggednpm · page 2 of 2.

A weathered combination padlock resting on a cracked concrete surface, surrounded by a tangled web of thin copper wires spreading outward in all directions, pho
Identity & Access

Poisoned Developer Tool Downloaded Nearly 1,500 Times Before Anyone Noticed

Criminals hijacked the publishing credentials for a widely used JavaScript security package and slipped malware into four releases over a single weekend. Developers who installed any of those versions may have handed over passwords, crypto-wallet keys, and cloud access tokens without knowing it.

3 min read
Illustration: A dim school computer lab at dusk, rows of identical monitors glowing with abstract blue browser windows
Threat Intelligence

Fake Student Proxies on npm Turned Browsers Into a DDoS Weapon

JFrog researchers say 148 malicious packages used npm as free hosting for a booby-trapped proxy site, quietly enlisting students' browsers into an attack campaign that ran for roughly two weeks in May 2024.

3 min read
Illustration: a developer's dark workstation at night
Threat Intelligence

Malicious Jscrambler npm package stole developer secrets for two hours before takedown

A poisoned release of the Jscrambler npm package was downloaded almost 1,500 times, scooping up cloud keys, wallet seed phrases and browser credentials before the company pulled it.

3 min read
Illustration: a darkened developer workstation with a terminal window glowing on the monitor
Threat Intelligence

Booby-trapped jscrambler npm release runs infostealer the moment you install it

Version 8.14.0 of a popular JavaScript protection package shipped with a hidden payload that fires during install, no code changes required from the developer.

3 min read
Illustration: a dimly lit developer workstation at night
Threat Intelligence

Attackers Hijacked Injective Labs' GitHub to Slip Wallet-Stealing Code Into npm

A tampered @injectivelabs/sdk-ts release quietly siphoned crypto wallet keys and seed phrases from developers who installed it.

4 min read
Illustration: a developer's dark wooden desk at night, a laptop screen glowing with abstract green code
Threat Intelligence

Poisoned Injective SDK on npm quietly stole crypto wallet keys for hours

A hijacked contributor account on GitHub pushed a booby-trapped version of a popular blockchain toolkit, siphoning seed phrases from any developer who ran the wrong function.

4 min read
Illustration: a darkened developer workstation with a large monitor showing abstract cascading package dependency graphs
Policy & Regulation

npm 12 Turns Off Auto-Run Install Scripts to Blunt Supply Chain Attacks

GitHub's package manager for JavaScript now ships with a safer default, and it retires a token type that let developers skip two-factor login.

3 min read
Illustration: a developer's dark wooden desk
Threat Intelligence

Fake Paysafe and Skrill SDKs on npm and PyPI Went After Developers' Secrets

A single attacker uploaded 17 lookalike payment packages that quietly stole API keys, cloud credentials and GitHub tokens from anyone who installed them.

4 min read
Illustration: A softly lit developer workspace at night with a laptop open showing a blurred terminal window and lines
AI Security

HalluSquatting: When AI Coding Helpers Invent Fake Software, Criminals Register It First

Researchers show how attackers can predict the fake package names AI assistants make up, then publish real malware under those names, waiting for developers to install the trap.

3 min read
Illustration: a cluttered developer's desk at night, glowing keyboard
Threat Intelligence

North Korean hackers flood open-source repositories with 108 booby-trapped packages

The Contagious Interview crew is back, seeding npm, Packagist, Go and Chrome with malware aimed at developers.

3 min read
Illustration for the story: Fake Rollup Helper Packages on npm Traced to North Korean Hackers
Threat Intelligence

Fake Rollup Helper Packages on npm Traced to North Korean Hackers

Two look-alike JavaScript packages copied a popular developer tool line-for-line, then quietly opened a back door onto the machines of anyone who installed them.

3 min read
Illustration: a developer workstation at night, multiple monitors showing dense terminal output and an open code editor
Threat Intelligence

Supply-Chain Attackers Hide Python Stealer in npm and Go Packages, Sidestep Lifecycle Scripts

JFrog flags two hijacked npm packages and a Go cluster that abuse VS Code tasks to drop a cross-platform infostealer, bypassing the script hooks defenders typically watch.

3 min read
Illustration for the story: Mini Shai-Hulud Worm Jumps to Go, Hits LeoPlatform and RStreams npm Packages
Threat Intelligence

Mini Shai-Hulud Worm Jumps to Go, Hits LeoPlatform and RStreams npm Packages

The self-propagating supply chain campaign tied to Miasma and Hades has spread again, abusing GitHub Actions workflows and now reaching Go modules.

3 min read
Illustration: a cluttered developer desk at night, mechanical keyboard glowing amber
Threat Intelligence

Three npm Packages Squat PostCSS Names to Drop a Windows RAT

Typosquatted utilities pulled roughly a thousand combined downloads before researchers flagged them. The payload targets Windows developer machines, which is exactly where the credentials live.

2 min read
© 2026 Threat Vectr